CVE-2007-3954
Microsoft Internet Explorer - XSS
Title source: ruleDescription
Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with SeaMonkey installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a mailto URI, which are inserted into the command line that is created when invoking SeaMonkey.exe, a related issue to CVE-2007-3670.
Scores
EPSS
0.0125
EPSS Percentile
79.1%
Classification
CWE
CWE-79
Status
draft
Affected Products (2)
microsoft/internet_explorer
mozilla/seamonkey
Timeline
Published
Jul 24, 2007
Tracked Since
Feb 18, 2026